logo

ClickUp Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants

ID: 82e14299-b831-5f06-85a9-46f96c9c58f1

STIX ID: report--82e14299-b831-5f06-85a9-46f96c9c58f1

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: AnuPriya

...
...

**Executive summary:** ClickUp exposed a hardcoded Split.io API token in its production JavaScript bundle, allowing unauthenticated access to backend data (including ~959 email addresses from Fortune 500 and government entities), and a webhook SSRF flaw that the researcher used to retrieve AWS IAM credentials; the vulnerabilities reportedly persisted for over a year despite prior reports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.